Full Report
Another few bite the dust
Analysis Summary
# Incident Report: Multi-Agency Takedown of ShinyHunters Affiliates
## Executive Summary
Following a series of high-profile data thefts and extortion attempts, the FBI and international law enforcement partners have arrested multiple key members associated with the "ShinyHunters" and "Scattered LAPSUS$ Hunters" threat groups. The arrests, including a suspected technical operator in Jordan and a primary leader in the Netherlands, follow a significant compromise of Jaguar Land Rover and a retaliatory hack against the FBI's own recruitment portal. The operation aims to dismantle the infrastructure and leadership of one of the most prolific extortion groups in recent years.
## Incident Details
- **Discovery Date:** September 2026 (Recent wave of arrests)
- **Incident Date:** Late August 2025 (JLR Hack); September 2026 (FBIJobs Hack)
- **Affected Organization:** Jaguar Land Rover (JLR), FBI (FBIJobs.gov), Various Others
- **Sector:** Automotive, Government, Multiple commercial sectors
- **Geography:** Global (Impact in UK/US; Arrests in Jordan and Netherlands)
## Timeline of Events
### Initial Access
- **Date/Time:** Late August 2025 (JLR Incident)
- **Vector:** Not explicitly detailed in this report, but attributed to "Scattered LAPSUS$ Hunters."
- **Details:** Initial breach targeted Jaguar Land Rover IT systems.
### Lateral Movement
- **Details:** Attackers successfully navigated from initial entry points to core manufacturing and dealer management systems, as well as HR databases containing employee records.
### Data Exfiltration/Impact
- **JLR Impact:** Compromise of thousands of employees' personal information.
- **FBI Impact:** Breach of FBIJobs.gov portal in late September 2026; theft of personal details belonging to current, former, and prospective FBI employees.
- **Extortion:** Data was used for public relations, marketing the "business" of the threat group, and retaliatory messaging against law enforcement.
### Detection & Response
- **Detection:** JLR incident detected via widespread operational failure. FBIJobs hack detected via public claims by the threat group.
- **Response Actions:**
- **Sept 16, 2026:** Dutch National Police arrest a 24-year-old leader (allegedly Pepijn van der Stap).
- **Sept 29, 2026:** Saif al-Din Khader (alias "Rey") detained in Jordan.
- **Ongoing:** FBI issued a public ultimatum to remaining members to surrender.
## Attack Methodology
- **Initial Access:** Likely Social Engineering or Credential Stuffing (typical for LAPSUS$ variants).
- **Persistence:** Not specified.
- **Privilege Escalation:** Not specified.
- **Defense Evasion:** Not specified.
- **Credential Access:** Theft of employee credentials via internal database access.
- **Discovery:** Mapping of manufacturing and dealer networks (JLR).
- **Lateral Movement:** Movement between corporate IT and manufacturing production environments.
- **Collection:** Bulk extraction of PII (Personally Identifiable Information).
- **Exfiltration:** Transfer of sensitive employee records to threat-actor-controlled servers.
- **Impact:** Operational disruption (manufacturing halt), data extortion, and reputational damage to federal agencies.
## Impact Assessment
- **Financial:** Massive loss due to manufacturing halts at JLR and canceled supplier orders.
- **Data Breach:** Thousands of PII records stolen from JLR and the FBI.
- **Operational:** Manufacturing operations halted for months; dealer systems rendered offline.
- **Reputational:** High-profile compromise of an FBI-affiliated portal used for recruitment.
## Indicators of Compromise
- **Network Indicators:** Traffic to/from FBIJobs\[.\]gov involving unauthorized API calls.
- **Behavioral Indicators:** Large-scale data transfers from HR databases; unauthorized access to manufacturing control systems.
- **Identified Actors:**
- Saif al-Din Khader (Alias: Rey)
- Pepijn van der Stap (Alleged leader)
## Response Actions
- **Containment:** FBI infrastructure reviewed following the September portal hack.
- **Eradication:** Arrest of key technical operators to degrade group capabilities.
- **Recovery:** Cooperation from detained suspects (Khader) to identify remaining members and infrastructure.
## Lessons Learned
- **Insider Risk/Prior Offenders:** One arrested suspect was on supervised release for prior hacking crimes, highlighting the high recidivism rate in cybercrime.
- **Interconnectivity:** The compromise of dealer systems showed how a breach in corporate IT can paralyze an entire supply chain and manufacturing floor.
- **Retaliatory Attacks:** Threat groups are increasingly using "PR hacks" against law enforcement to protest official statements, rather than purely for financial gain.
## Recommendations
- **Multi-Factor Authentication (MFA):** Ensure robust MFA is applied to all portals, including recruitment and legacy manufacturing interfaces.
- **Network Segmentation:** Strictly isolate manufacturing/production networks from corporate IT and public-facing web portals.
- **Supply Chain Security:** Implement contingency plans for dealers and suppliers when central IT hubs are compromised.
- **Enhanced Monitoring:** Increase logging and alerting on portals containing sensitive PII (like FBIJobs) for unusual egress patterns.